CS Google Analytics Security & Risk Analysis

wordpress.org/plugins/cs-google-analytics-code

A simple plugin to populate the google analytics code in the head section.

10 active installs v1.0.2 PHP + WP 4.5+ Updated Sep 26, 2019
ga-codegoogle-analyticsgoogle-analytics-code-verificationswordpress-google-analyticswp-google-analytics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CS Google Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

CS Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "cs-google-analytics-code" plugin v1.0.2 presents a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests, all of which are good security practices. The use of prepared statements for all SQL queries is commendable, mitigating the risk of SQL injection. However, the analysis does reveal some areas for concern. With only 67% of outputs properly escaped, there is a residual risk of Cross-Site Scripting (XSS) vulnerabilities in the 33% of unescaped outputs. The lack of nonce checks and capability checks, while not directly tied to an identified attack surface in this version, suggests a potential weakness that could be exploited if new entry points were introduced without proper security hardening. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its past security performance.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

CS Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CS Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

CS Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menucs-google-analytics.php:37
actionadmin_initcs-google-analytics.php:38
actionwp_headcs-google-analytics.php:42
Maintenance & Trust

CS Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 26, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

CS Google Analytics Developer Profile

catchsquare

5 plugins · 10K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
159 days
View full developer profile
Detection Fingerprints

How We Detect CS Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/cs-google-analytics-code/images/ga-icon.png

HTML / DOM Fingerprints

CSS Classes
form-control
HTML Comments
google analytics code added by CAS-google analytics plugins
Data Attributes
name="csa-google-analytics[csa_google_analytics_number]"
JS Globals
ga
FAQ

Frequently Asked Questions about CS Google Analytics